Re: [logs] "Temperproof" logfiles?

From: Chris Lonvick (clonvickat_private)
Date: Tue Mar 25 2003 - 20:24:11 PST

  • Next message: Limpach, Patrick: "[logs] Bracket source IP address in syslog files"

    Hi,
    
    Albert Mietus put together an implementation of syslog-sign and presented
    that at eurobsdcon a while ago.  You might try tracking that down.
    syslog-sign is described here:
      http://www.ietf.org/internet-drafts/draft-ietf-syslog-sign-09.txt
    
    Best of Luck,
    Chris
    
    On Wed, 26 Mar 2003, Michael Boman wrote:
    
    > Hi all,
    >
    > I am looking for a syslog (the old, udp one) software that makes sure that
    > the integrity of the logs has not been modified since they was recived. I
    > have looked at mSyslog, but the problem with that one is that I find it
    > unstable and it totally locks up if one of the output modules doesn't
    > work (we  want the logs in a database for ease of searching as well as
    > normal file for long-time storage). Syslog-ng seems to do what we want
    > for the database part, but how about making sure that the logfiles was
    > not subsequently changed after they were recived?
    >
    > Does anyone know any software that does this?
    >
    > Best regards
    >  Michael Boman
    >
    > --
    > Michael Boman
    > Security Architect, SecureCiRT Pte Ltd
    > http://www.securecirt.com
    >
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Tue Mar 25 2003 - 20:30:41 PST